Omahub
← All plugins
M

Fast: Network Speed Test

by melonamin

A terminal-inspired Fast.com speed test for the Omarchy bar

Security review

Potentially dangerous behavior detected · 2 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
d95d08a
Scanned
2 weeks ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d95d08a
Reviewed
2 weeks ago

The high deterministic rating is driven entirely by the bundled systemd timer/service files, but these are user-level, opt-in, and documented, and they only run the plugin's own speed-test script, so they do not represent malware-style persistence. The remaining code is transparent: fixed command paths, no obfuscation, no credential access, and no destructive install-time behavior. The widget is safe to publish; the only residual consideration is the user-enabled daily network test.

  • The bundled systemd units are flagged as persistence; they are safe here, but the plugin manager should not auto-enable them, since the README correctly requires an explicit user `systemctl --user enable` step.
  • The monitor service assumes the plugin lives under `~/.config/omarchy/plugins/melonamin.fast`; if Omarchy uses a custom `XDG_CONFIG_HOME`, the timer path may not match, though this is a compatibility issue rather than a security risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/melonamin/omarchy-fast --enable
Widgets #bar #quickshell

Fast for Omarchy

A terminal-inspired Fast.com speed test for the Omarchy bar. It uses Omarchy's own omarchy-network-speedtest backend for both on-demand and passive scheduled tests.

Fast showing a completed network speed test and recent history

Install

omarchy plugin add https://github.com/melonamin/omarchy-fast.git --enable

The widget is added to the right side of the bar. Remove it with:

omarchy plugin remove melonamin.fast

Use

  • Left click: open the terminal panel
  • Middle click: start a fresh terminal test
  • Enter or r: run again
  • Esc: close and stop an active test

Download and upload run for five seconds each and are sampled ten times per second from the active interface. The displayed result averages the settled samples after the warm-up; peak remains the highest live reading. A process-group guard ensures every transfer worker stops when its phase ends or the panel is dismissed. One parent lock spans both interactive phases, so the passive timer cannot slip between download and upload. Sampling begins only after the Fast.com backend emits its first live reading and the active interface records transferred bytes; endpoint discovery or traffic generation that fails or stalls is reported as an error rather than being saved as a near-zero result.

The live rate eases between samples while a glowing trace, speed-reactive directional streaks, scan flares, endpoint sparks, and a layered two-color completion burst add motion without abandoning the terminal look.

The latest eight completed runs are stored below XDG_STATE_HOME (falling back to ~/.local/state/omarchy/plugins/melonamin.fast/history.json) and shown newest first in the panel.

State access goes through the bundled safe-state helper. It walks the state directory without following symlinks, keeps lock and temporary-file descriptors open, accepts only user-owned regular files, caps history reads at 64 KiB, and replaces history atomically. The long-lived shell never opens or watches the history pathname directly.

Requirements

Omarchy 4 (Quattro) or newer, running omarchy-shell. Python 3 is required at runtime for descriptor-safe local state access. The stock Omarchy installation provides Python, the speed-test backend, and the other command-line tools used by the plugin. Node is required only for the model test suite.

Passive monitoring

melonamin-fast-monitor.timer runs a quieter three-second-per-direction test daily at 4:00 AM local time, with up to 30 minutes of randomized delay. The timer is persistent, so a sleeping machine catches up after it wakes. Automatic history rows use an A prefix; manual rows retain their numeric prefix. A failed catch-up retries twice at one-minute intervals, allowing networking a short window to reconnect after wake.

The monitor stays silent, skips if another test is already running, and records its result in the same eight-entry history. It is optional; install and enable the bundled user units with:

plugin_dir="${XDG_CONFIG_HOME:-$HOME/.config}/omarchy/plugins/melonamin.fast"
systemctl --user link \
  "$plugin_dir/systemd/melonamin-fast-monitor.service" \
  "$plugin_dir/systemd/melonamin-fast-monitor.timer"
systemctl --user enable --now melonamin-fast-monitor.timer

Inspect the next run with:

systemctl --user list-timers melonamin-fast-monitor.timer

Disable and unlink the monitor before removing the plugin:

systemctl --user disable --now melonamin-fast-monitor.timer
systemctl --user unlink \
  melonamin-fast-monitor.service \
  melonamin-fast-monitor.timer

Tests

bash -n run-interactive-test run-scheduled-test run-speedtest tests/*.sh
tests/failure.test.sh
tests/interactive.test.sh
tests/scheduled.test.sh
tests/integration.sh
python3 tests/state.test.py
node --test tests/model.test.js
qmllint BarWidget.qml Panel.qml SignalTrace.qml SparkBurst.qml SpeedRow.qml Model.js
omarchy plugin validate .
systemd-analyze --user verify systemd/*.service systemd/*.timer

The integration test performs a real three-second download measurement.

License

MIT